CVE-2011-2731
Summary
| CVE | CVE-2011-2731 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-05 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Springsource Spring Security | 2.0.0 | All | All | All |
| Application | Vmware | Springsource Spring Security | 2.0.1 | All | All | All |
| Application | Vmware | Springsource Spring Security | 2.0.2 | All | All | All |
| Application | Vmware | Springsource Spring Security | 2.0.3 | All | All | All |
| Application | Vmware | Springsource Spring Security | 2.0.4 | All | All | All |
| Application | Vmware | Springsource Spring Security | 2.0.5 | All | All | All |
| Application | Vmware | Springsource Spring Security | 3.0.0 | All | All | All |
| Application | Vmware | Springsource Spring Security | 3.0.1 | All | All | All |
| Application | Vmware | Springsource Spring Security | 3.0.2 | All | All | All |
| Application | Vmware | Springsource Spring Security | 3.0.3 | All | All | All |
| Application | Vmware | Springsource Spring Security | 3.0.4 | All | All | All |
| Application | Vmware | Springsource Spring Security | All | All | All | All |
| Application | Vmware | Springsource Spring Security | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix CloudPortal Business Manager Lets Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMware Tanzu Application Security Team | VMware Tanzu | af854a3a-2127-422b-91ae-364da2661108 | support.springsource.com | Vendor Advisory |
| #677814 - CVE-2011-2730 - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Security Advisory SA55155 - Citrix CloudPortal Business Manager Two Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.